Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds Adobe and WSO2 Flaws to Known Exploited Vulnerabilities Catalog: A Growing Concern for Cybersecurity




The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities, CVE-2026-5430 and CVE-2026-71362, affect Adobe Commerce and Magento, as well as WSO2 products. Experts recommend that organizations review the CISA catalog and address the vulnerabilities in their infrastructure to protect against potential attacks. With the CVSS scores indicating a high level of severity, it is essential to prioritize security and take proactive steps to mitigate the risk of exploitation.

  • CISA has added two new vulnerabilities to its KEV catalog: CVE-2026-5430 and CVE-2026-71362.
  • CVE-2026-5430 is an authentication bypass vulnerability in multiple WSO2 products with a CVSS score of 10.0.
  • CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce with a CVSS score of 9.1.
  • Both vulnerabilities have significant implications for organizations using Adobe Commerce, Magento, and WSO2 products.
  • CISA orders federal agencies to fix the flaws by September 27, 2026.
  • Experts recommend reviewing the KEV catalog, using isolated patches, and having robust security measures in place.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The two vulnerabilities, CVE-2026-5430 and CVE-2026-71362, have been identified as critical security flaws in Adobe Commerce and Magento, as well as WSO2 multiple products, respectively.

    The first vulnerability, CVE-2026-5430, is an authentication bypass vulnerability in multiple WSO2 products. This flaw allows an attacker to exploit an unsupported signing algorithm, enabling them to gain unauthorized access and potentially take over accounts. The vulnerability has a CVSS score of 10.0, indicating a high level of severity. Cybersecurity firm Sansec has already blocked the first exploitation attempts after Adobe published its advisory, urging users to patch the vulnerability.

    The second vulnerability, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe Commerce. This flaw allows an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction. The vulnerability has a CVSS score of 9.1 and has been targeted by hackers shortly after its public disclosure. Sansec has also confirmed that the vulnerability lets attackers switch a customer session to another customer account, giving them access to the victim's account and private customer data.

    Both vulnerabilities have significant implications for organizations that use Adobe Commerce and Magento, as well as WSO2 products. The CISA orders federal agencies to fix the flaws by September 27, 2026, highlighting the importance of addressing these vulnerabilities to protect against attacks exploiting the flaws in the catalog.

    Experts recommend that private organizations review the CISA catalog and address the vulnerabilities in their infrastructure. The use of isolated patches and regular software updates can help mitigate the risk of exploitation. Furthermore, organizations should ensure that they have robust security measures in place to detect and respond to potential attacks.

    The addition of these vulnerabilities to the KEV catalog underscores the growing concern for cybersecurity in the modern era. As more and more vulnerabilities are discovered, it is essential for organizations to prioritize security and take proactive steps to protect themselves against potential threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Adobe-and-WSO2-Flaws-to-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml

  • https://securityaffairs.com/199704/hacking/u-s-cisa-adds-adobe-and-wso2-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html

  • https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

  • https://nvd.nist.gov/vuln/detail/CVE-2026-5430

  • https://www.cvedetails.com/cve/CVE-2026-5430/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-71362

  • https://www.cvedetails.com/cve/CVE-2026-71362/


  • Published: Fri Sep 25 05:10:43 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us